CVE Vulnerabilities

CVE-2007-3511

Published: Jul 03, 2007 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

The focus handling for the onkeydown event in Mozilla Firefox 1.5.0.12, 2.0.0.4 and other versions before 2.0.0.8, and SeaMonkey before 1.1.5 allows remote attackers to change field focus and copy keystrokes via the for attribute in a label, which bypasses the focus prevention, as demonstrated by changing focus from a textarea to a file upload field.

Affected Software

NameVendorStart VersionEnd Version
FirefoxMozilla*2.0.0.7 (including)
FirefoxMozilla1.5.0.12 (including)1.5.0.12 (including)
FirefoxMozilla2.0.0.4 (including)2.0.0.4 (including)
FirefoxMozilla2.0.0.5 (including)2.0.0.5 (including)
FirefoxMozilla2.0.0.6 (including)2.0.0.6 (including)
SeamonkeyMozilla*1.1.4 (including)
SeamonkeyMozilla1.0 (including)1.0 (including)
SeamonkeyMozilla1.0-alpha (including)1.0-alpha (including)
SeamonkeyMozilla1.0-beta (including)1.0-beta (including)
SeamonkeyMozilla1.0.1 (including)1.0.1 (including)
SeamonkeyMozilla1.0.2 (including)1.0.2 (including)
SeamonkeyMozilla1.0.3 (including)1.0.3 (including)
SeamonkeyMozilla1.0.4 (including)1.0.4 (including)
SeamonkeyMozilla1.0.5 (including)1.0.5 (including)
SeamonkeyMozilla1.0.6 (including)1.0.6 (including)
SeamonkeyMozilla1.0.7 (including)1.0.7 (including)
SeamonkeyMozilla1.0.8 (including)1.0.8 (including)
SeamonkeyMozilla1.0.9 (including)1.0.9 (including)
SeamonkeyMozilla1.0.99 (including)1.0.99 (including)
SeamonkeyMozilla1.1 (including)1.1 (including)
SeamonkeyMozilla1.1.1 (including)1.1.1 (including)
SeamonkeyMozilla1.1.2 (including)1.1.2 (including)
SeamonkeyMozilla1.1.3 (including)1.1.3 (including)
Red Hat Enterprise Linux 2.1RedHatseamonkey-0:1.0.9-0.6.el2*
Red Hat Enterprise Linux 3RedHatseamonkey-0:1.0.9-0.5.el3*
Red Hat Enterprise Linux 4RedHatfirefox-0:1.5.0.12-0.7.el4*
Red Hat Enterprise Linux 4RedHatseamonkey-0:1.0.9-6.el4*
Red Hat Enterprise Linux 4RedHatthunderbird-0:1.5.0.12-0.5.el4*
Red Hat Enterprise Linux 5RedHatfirefox-0:1.5.0.12-6.el5*
Red Hat Enterprise Linux 5RedHatthunderbird-0:1.5.0.12-5.el5*
FirefoxUbuntudapper*
FirefoxUbuntuedgy*
FirefoxUbuntufeisty*
FirefoxUbuntugutsy*
FirefoxUbuntuupstream*
Mozilla-thunderbirdUbuntudapper*
Mozilla-thunderbirdUbuntuedgy*
Mozilla-thunderbirdUbuntufeisty*
ThunderbirdUbuntugutsy*
ThunderbirdUbuntuupstream*

References